SB20250226700 - Resource management error in Linux kernel cpufreq driver
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2022-49513)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the free_policy_dbs_info(), cpufreq_dbs_governor_init() and cpufreq_dbs_governor_exit() functions in drivers/cpufreq/cpufreq_governor.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1e32083f327184b6226ce320ef30085ce785ea4e
- https://git.kernel.org/stable/c/a1964688582d26af1328e19b658933659fb54337
- https://git.kernel.org/stable/c/a85ee6401a47ae3fc64ba506cacb3e7873823c65
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.91
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19